SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-5016

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13…

MEDIUM 5.9EPSS 1.03%

Does this matter?

Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.

Description

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.03% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
pivotal software/cloud foundry · pivotal software/cloud foundry elastic runtime · pivotal software/cloud foundry uaa · pivotal software/cloud foundry uaa-release
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.